3 checks that ran failed — injection surface, credential hygiene and transport config — so this release can’t be trusted as-is.
- Publisher
- ai.intuitek.the-stall
- Repository
- —
- Install
- remote only
- Versions
- 204
- MCP revision
- 2025-11-25 · superseded
- Inspected
- 4 of 6 checks · 75%
- Scored
- 2026-09-04 · rubric 1.0.0
What we checked
Six static checks, weighted by risk. Every result reflects only what could be observed in the published package and repository — never intent.
Injection surface
fail25% of gradeTool descriptions/manifest scanned for instruction-injection patterns (imperatives at the model, hidden text, 'ignore previous', data-exfil URLs).
tool "llm-proxy" param "prompt" description: text addressed to the model rather than describing a capability. tool "agent-access-check" param "url" description: off-vendor URL in a description (example.com); capability text should not name where data goes. tool "code-security-scan" param "repo_url" description: off-vendor URL in a description (github.com); capability text should not name where data goes. tool "company-research-bundle" param "website_url" description: off-vendor URL in a description (stripe.com); capability text should not name where data goes. tool "github-org-intel" param "org" description: off-vendor URL in a description (github.com); capability text should not name where data goes. tool "github-repo-intel" param "repo" description: off-vendor URL in a description (github.com); capability text should not name where data goes. tool "wayback-intel" param "url" description: off-vendor URL in a description (sec.gov); capability text should not name where data goes. tool "web-company-intel" param "url" description: off-vendor URL in a description (stripe.com); capability text should not name where data goes. tool "x402-endpoint-intel" param "target" description: off-vendor URL in a description (…); capability text should not name where data goes.
Supply chain
warn25% of gradePackage provenance: namespace verification, repo linkage, maintainer count, account age, postinstall scripts, typosquat distance.
no resolvable repository linked to the package (provenance unverifiable)
Credential hygiene
fail15% of gradeHow the server takes secrets (env vs plaintext config vs hardcoded); secrets appearing in tool schemas.
tool "dex-swap-quote" has a secret-shaped input parameter "from_token" — secrets must never be tool parameters (the model would supply/handle the credential). tool "dex-swap-quote" has a secret-shaped input parameter "to_token" — secrets must never be tool parameters (the model would supply/handle the credential). tool "nft-metadata" has a secret-shaped input parameter "token_id" — secrets must never be tool parameters (the model would supply/handle the credential). tool "token-top-holders" has a secret-shaped input parameter "token_address" — secrets must never be tool parameters (the model would supply/handle the credential).
Permission scope
unscannable15% of gradeDeclared tools vs. breadth (filesystem, network, exec); flags shell-exec and unbounded filesystem access.
No source files, package.json, or pyproject were fetched; cannot infer capability scope.
Version behavior
unscannable10% of gradeDiff of tool definitions between versions; new permissions or changed descriptions in a patch release (the postmark-mcp class).
no prior version to diff (first sight of ai.intuitek.the-stall/[email protected]); version-drift / rug-pull cannot be evaluated. Cold-start risk is covered by point-in-time checks (injection_surface, supply_chain, credential_hygiene), not here.
Transport config
fail10% of gradeRemote servers: TLS and auth mode (none/token/OAuth). Local servers: whether the manifest indicates it phones home.
remote MCP endpoint declares NO authentication (unauthenticated remote — nginx-ui/CVE-2026-33032 class)
Version history
Each release plotted by grade against the safe line at B. A version that sinks below the line has lost its trusted standing — the shape of a rug-pull.
| Version | Published | Grade | Score | Inspected | Change |
|---|---|---|---|---|---|
| vv4.82.0 · current | 2026-06-29 | F | 37.5 | 4/6 · 75% | ±0 |
| v4.69.0 | 2026-06-25 | F | 37.5 | 4/6 · 75% | ±0 |
| v4.68.4 | 2026-06-25 | F | 37.5 | 4/6 · 75% | ±0 |
| v4.68.0 | 2026-06-25 | F | 37.5 | 4/6 · 75% | ±0 |
| v4.47.0 | 2026-06-09 | F | 37.5 | 4/6 · 75% | insf→F in v4.47.0 |
| v4.35.0 | 2026-06-08 | insufficient | — | 2/6 · 35% | ±0 |
| v4.33.0 | 2026-06-08 | insufficient | — | 2/6 · 35% | ±0 |
| v4.32.0 | 2026-06-08 | insufficient | — | 1/6 · 25% | B→insf in v4.32.0 |
| v4.22.0 | 2026-06-07 | B | 77.5 | 4/6 · 75% | F→B in v4.22.0 |
| v4.14.0 | 2026-06-07 | F | 37.5 | 4/6 · 75% | ±0 |
| v4.10.0 | 2026-06-07 | F | 37.5 | 4/6 · 75% | ±0 |
| v3.87.0 | 2026-06-07 | F | 37.5 | 4/6 · 75% | ±0 |
| v3.84.0 | 2026-06-07 | F | 37.5 | 4/6 · 75% | ±0 |
| v3.80.0 | 2026-06-07 | F | 37.5 | 4/6 · 75% | ±0 |
| v3.45.0 | 2026-06-06 | F | 37.5 | 4/6 · 75% | insf→F in v3.45.0 |
| v3.32.0 | 2026-06-06 | insufficient | — | 2/6 · 35% | ±0 |
| v3.31.0 | 2026-06-06 | insufficient | — | 2/6 · 35% | ±0 |
| v3.30.0 | 2026-06-06 | insufficient | — | 1/6 · 25% | B→insf in v3.30.0 |
| v3.23.0 | 2026-06-06 | B | 77.5 | 4/6 · 75% | F→B in v3.23.0 |
| v3.15.0 | 2026-06-06 | F | 37.5 | 4/6 · 75% | ±0 |
| v3.10.0 | 2026-06-06 | F | 37.5 | 4/6 · 75% | — |